Weaknesses of type CWE-267

65 results

Privilégio definido com ações inseguras

Quando uma aplicação concede um nível de privilégio ou papel (role) que permite executar ações perigosas sem validação ou proteção adequada. O desenvolvedor cria uma função administrativa ou de confiança, mas não implementa verificações suficientes antes de deixar que essa função faça operações críticas como deletar dados, alterar configurações de segurança ou acessar informações sensíveis.

Example

Um painel de admin que deixa qualquer usuário com role 'gerente' deletar contas de clientes sem auditoria, confirmação em dois passos ou log de quem deletou — permitindo que um gerente desgrenhado ou comprometido cause dano massivo sem deixar rastreamento claro ou sem possibilidade de reverter.

How to mitigate

Separe privilégios por granularidade (ex: 'deletar_conta' diferente de 'editar_perfil'); exija validações extras para ações destrutivas (confirmação, segundo fator, revisão); implemente auditoria completa de quem fez o quê; use o princípio do menor privilégio — nunca dê mais permissão que o estritamente necessário para a função.

CVE-2026-27314HIGHApache Cassandra: Privilege escalation via ADD IDENTITY authorization bypassEPSS 0.3%CVE-2024-7571HIGHIncorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.3%CVE-2026-23526HIGHCVAT vulnerable to privilege escalation of users with staff statusEPSS 0.3%CVE-2026-10090CRITICALMulticluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscriptionEPSS 0.2%CVE-2024-39866HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to uploEPSS 0.2%CVE-2024-47906HIGHExcessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before versiEPSS 0.2%CVE-2026-0945MEDIUMRole Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002EPSS 0.2%CVE-2024-8539HIGHImproper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configEPSS 0.2%CVE-2024-9842HIGHIncorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary foldersEPSS 0.2%CVE-2023-44218HIGH A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system EPSS 0.2%CVE-2025-62588HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-2903HIGHPrivilege Chaining in DelphixEPSS 0.2%CVE-2025-62589HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62641HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62590HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62591MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62587HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2024-5623MEDIUMUntrusted search path vulnerability in B&R APROLEPSS 0.2%CVE-2024-5622HIGHUntrusted search path vulnerability in the AprolConfigureCCServices of B&R APROLEPSS 0.2%CVE-2024-20411MEDIUMCisco NX-OS Bash Arbitrary Code Execution VulnerabilityEPSS 0.2%